In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317.
The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Software_development_kit | Mediatek | * | 3.7 (including) |
Android | 13.0 (including) | 13.0 (including) | |
Android | 14.0 (including) | 14.0 (including) | |
Android | 15.0 (including) | 15.0 (including) | |
Openwrt | Openwrt | 21.02.0 (including) | 21.02.0 (including) |
Openwrt | Openwrt | 23.05 (including) | 23.05 (including) |